S4E just found a high-severity finding from cve-2001-1473 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-43778 Scanner

Detects 'Path Traversal' vulnerability in pluginsGLPI barcode affects v. from 2.x prior to 2.6.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-43778
7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal vulnerability. This issue was patched in version 2.6.1. As a workaround, delete the `front/send.php` file.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
barcodeby pluginsGLPI
>= 2.0.0, < 2.6.1
Updated Aug 21, 2026View on NVD →
Detail

GLPI Barcode plugin is a useful tool designed for printing barcodes and QR codes. This plugin is used in GLPI instances version 2.x. Its multiple features make the barcode management process streamlined and efficient. The barcodes are extremely important for product identification and inventory management. The plugin makes it easier for individuals and organizations to keep track of their assets, saving them valuable time and minimizing the likelihood of error.

CVE-2021-43778 vulnerability has been detected in the GLPI Barcode plugin. This vulnerability specifically targets version 2.x prior to version 2.6.1. The vulnerability allows an attacker to exploit a path traversal vulnerability in the system. Path traversal is a technique that allows attackers to gain unauthorized access to directories. In the GLPI Barcode plugin, the vulnerability is present in the send.php file. This file can be exploited by attackers to gain unauthorized access to sensitive information.

When exploited, this vulnerability can lead to serious consequences. Attackers can gain access to sensitive information, such as customer data, product information, and financial data. The attacker can also inject malware and scripts in the system, giving them access to unauthorized control over the system. This can result in loss of data, system downtime, and financial loss.

By using the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. This platform provides a comprehensive vulnerability assessment that helps identify vulnerabilities on the system. Users can also access detailed reports based on their individual needs. The platform helps users to stay secure with minimal effort and minimal risk of exposure. It is the perfect solution for organizations that require an easy, cost-effective, and reliable way to maintain their security posture.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following steps:

  • Update to version 2.6.1 or later of GLPI
  • Delete the front/send.php file as a workaround
  • Implement a robust security posture, including policies and procedures
  • Conduct regular vulnerability assessments and penetration testing
  • Create a backup of critical data.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-43778 scanner - Path Traversal vulnerability in pluginsGLPI barcode | S4E